And, you also need to remember that NIST seems to have known about "differential cryptanalysis" before everybody else and made DES actually more resistant to it.
"Trust, but verify" should always be the rule.
NIST submitted the AES candidates to the NSA for feedback and the NSA proposed S-box changes without explaining why.
Turns out hose changes made AES more resilient to differential cryptography.
Once upon a time, NIST arranged a public, open competition for a symmetric encryption algorithm, and received several submissions from multiple teams of cryptographers, such as Bruce Schneier (TwoFish), Ron Rivest (RC6), and IBM (Serpent). One scheme was submitted by two cryptographers from Belgium: Vincent Rijmen and Joan Daemen. It survived multiple rounds of reviews by other cryptographers inside and outside the NIST. Finally, Rijndael becomes AES. Although it suffers from minor imperfections, such as timing hazards, or related-key hazard in AES-256. It's universally recognized as the solid standard of symmetric encryption.
Another time, NIST arranged another public competition, it received several submissions from multiple teams of cryptographers. The scheme purposed by the Keccak team, ultimately becomes SHA-3. It doesn't use the classic Merkle–Damgard struction, it's immune from length-extension attacks and arguable more secure than SHA-2, which is designed by the NSA. Yet another time, NIST arranged another public, open competition, and it gave us Argon2, and currently it's considered one of the best password hashing scheme against GPU attacks.
And yet another time, NIST didn't arrange any competition, it gave us Dual_EC. Or the parameters for the NIST curves. But their problems were quickly identified by the public as well. When NIST curves were first announced, it received immediate criticisms on the Usenet. The Dual_EC case was more obvious - even before it was formally published in 2007, the possibility of an asymmetric backdoor was already shown by researchers, yet, despite the criticisms from the public, the NIST still standardized it. The documents from Snowden simply confirms the widespread suspicion.
But when it comes to open competitions, the NIST primarily provides a public platform for researchers, so the U.S. Government could know what is secure by receiving a complete and free cryptanalysis from the best cryptographers. Unless you believe in the conspiratorial view of history, and all the prominent cryptographers around the world are all under secret control of the NSA, there is no reason to believe the results from these open competitions under the scrutiny of public reviews are compromised. Yes, it's possible that the NIST will manipulate the final result during the standardization process, but if it happens, you are free to use the non-standard version.
For example, the standard SHA-3 has different parameters from the original one of the Keccak team. The NIST said it was the tradeoff between acceptable security and performance. Although there is zero evidence of wrongdoings, in case you have reason to believe the standard parameters are backdoored, free to use the original Keccak function, or you can just use BLAKE.
My point is, yes, the final standard may be backdoored, yes, the NSA may manipulate the industry to adopt problematic standards, and yes, sometimes there are reasons to distrust standards and their commercial products. But no, there is no reason to believe that the studies and findings from a public competition itself is harmful or backdoorod. The raw research during the competition is valid and valuable.
And there is even less reason to worry about the PQC competition. Currently, our understanding of Post-Quantum Cryptography is rather limited (some are well-understood and people have strong confidence, such as classical McEliese, or hash-based signatures, but performance is low, keysize is huge, unsuitable for many applications, people are searching for more efficient versions), some algorithms are purposed and broken within months. Around 20 submissions from the first round have already been broken.
I think even the NIST cannot be certain about the security currently... So now it's still in the Research stage. We can start worrying about backdoors in 2022, but probably, not now.
The NIST is a known danger - they have earned their reflexive blind distrust. I wouldn't even trust their relative rankings.
Yes, there is a difference. It's always possible that the telephone traffic is being intercepted by some entities, like Room 641A.
On the other hand, a proper random number generator or a public-key encryption algorithm shouldn't even have the theoretical possibility of introducing a backdoor to start with. When cryptographers have published papers that give strong proof that an algorithm is designed to be able to theoretically contain a backdoor, you know something is seriously wrong.
> they have earned their reflexive blind distrust.
Of course, after Snowden has presented his evidence, everybody now understands that everything that designed to be backdoored, will be backdoored. If NIST is purposing a new standard, it will be definitely taken with a grain of salt.
I think I've made the points clear,
> yes, the final standard may be backdoored, yes, the NSA may manipulate the industry to adopt problematic standards, and yes, sometimes there are reasons to distrust standards and their commercial products. But no, there is no reason to believe that the studies and findings from a public competition itself is harmful or backdoorod. The raw research during the competition is valid and valuable.
The vast majority of research is taking place OUTSIDE of the NIST, until the late stage, NIST is merely a forum for everyone, including the NIST people, to submit their comments and attacks. Once we have reached to the final round, the NIST will pick a winner and standardize it. And perhaps add a backdoor.
The point is, if something looks fishy, you don't have to use the one NIST standardized. You can simply choose other finalist, or even create your own, based on the knowledge of secure construction which is shown during the competition. Normally, at this point, the competition has already given enough information about what is secure and what is not.
To summarize, NIST standards may be bad, but the knowledge obtained during the research for the competition is always good.
In 2022, if NIST starts standardize something, then your comment makes perfect sense. But it's largely off-topic for the current moment.
I think it may be a viable alternative in the future. If everyone's having problems with NIST, perhaps we can have more non-governmental competitions organized by the academics and the industry in the future, just like Password Hashing Competition. I believe the CAESAR competition is also non-governmental, and has made great results as well.